Uptime Hamster: 22d 2h 32mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Blackoutware

Blackoutware

0 incidentes 0 paises 0 sectores ransomware null Ultimo: -
Ver en IntelTracker → APTTrail →
Blackoutware is a ransomware-as-a-service (RaaS) operation that was first observed in late 2023. It functions as a financially motivated cybercrime group, deploying ransomware that encrypts user files and threatens data exfiltration to coerce victims into paying a ransom. The group is distinguished by its use of the '.blo' extension for encrypted files and a specific ransom note titled '!!! WARNING!!!.txt'. It operates under a double-extortion model, combining file encryption with the threat of public data leakage if demands are not met.
Tecnicas MITRE
T1486 - Data Encrypted for Impact, T1490 - Inhibit System Recovery, T1567 - Exfiltration Over Web Service
Tipo
ransomware
Pais origen
null
Motivacion
-
Impacto
38
Actualizado
Fri, 19 Ju

Paises objetivo (SOCRadar)

AustraliaCanadaGermanySpainFranceUnited KingdomCroatiaItalyJapanKorea, Republic of

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingManufacturingConstructionPublic AdministrationEducational ServicesWholesale TradeEnergy & Utilities Accommodation&Food ServicesNational Security&International Affairs